Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

Grafana

Grafanaсвободная программная система визуализации данных, ориентированная на данные систем ИТ-мониторинга.

Релизный цикл, информация об уязвимостях

Продукт: Grafana
Вендор: grafana

График релизов

12.413.013.113.2202620272028

Релизные элементы

KBВерсияБилдДата доступности
11.6.1611.6.16
11.6.1511.6.15
11.6.1411.6.14+security-04
11.6.1411.6.14+security-01
11.6.1411.6.14
11.6.1311.6.13
11.6.1211.6.12
11.6.1111.6.11
11.6.1011.6.10+security-01
11.6.1011.6.10

Показывать по

Недавние уязвимости Grafana

Количество 593

redhat логотип

CVE-2026-33382

3 месяца назад

Several Grafana API endpoints, some of them unauthenticated, do not limit the size of the request body before processing it. An attacker can send very large payloads that force excessive memory allocation, potentially exhausting memory and causing a denial of service.

CVSS3: 5.3
EPSS: Низкий
github логотип

GHSA-x94r-qqxh-wpj5

3 месяца назад

The public dashboard deletion endpoint does not enforce organization isolation, allowing an Org Admin in one organization to delete public dashboards belonging to a different organization by supplying the target dashboard's identifiers.

CVSS3: 3.1
EPSS: Низкий
nvd логотип

CVE-2026-28378

3 месяца назад

The public dashboard deletion endpoint does not enforce organization isolation, allowing an Org Admin in one organization to delete public dashboards belonging to a different organization by supplying the target dashboard's identifiers.

CVSS3: 3.1
EPSS: Низкий
redhat логотип

CVE-2026-28378

3 месяца назад

The public dashboard deletion endpoint does not enforce organization isolation, allowing an Org Admin in one organization to delete public dashboards belonging to a different organization by supplying the target dashboard's identifiers.

CVSS3: 3.1
EPSS: Низкий
fstec логотип

BDU:2026-12021

3 месяца назад

Уязвимость платформы для мониторинга и наблюдения Grafana, связанная с недостатками контроля доступа. Эксплуатация уязвимости может позволить нарушителю повысить свои привилегии

CVSS3: 2.7
EPSS: Низкий
github логотип

GHSA-3w66-95m3-8jxg

3 месяца назад

The public dashboard query endpoint does not limit request body size before processing, allowing unauthenticated attackers to trigger excessive memory allocation by sending arbitrarily large JSON payloads. This can lead to denial of service through memory exhaustion. No valid dashboard access token or authentication is required to exploit this vulnerability.

CVSS3: 7.5
EPSS: Низкий
nvd логотип

CVE-2026-42127

3 месяца назад

The public dashboard query endpoint does not limit request body size before processing, allowing unauthenticated attackers to trigger excessive memory allocation by sending arbitrarily large JSON payloads. This can lead to denial of service through memory exhaustion. No valid dashboard access token or authentication is required to exploit this vulnerability.

CVSS3: 7.5
EPSS: Низкий
ubuntu логотип

CVE-2026-42127

3 месяца назад

The public dashboard query endpoint does not limit request body size before processing, allowing unauthenticated attackers to trigger excessive memory allocation by sending arbitrarily large JSON payloads. This can lead to denial of service through memory exhaustion. No valid dashboard access token or authentication is required to exploit this vulnerability.

CVSS3: 7.5
EPSS: Низкий
github логотип

GHSA-9g84-39mm-q4p3

3 месяца назад

The geomap panel's XYZ tile layer has a sanitize-then-interpolate ordering bug. sanitizeTextPanelContent() runs on the raw template string before getTemplateSrv().replace() substitutes the variable value, which uses the glob format with no HTML escaping. The result is passed to OpenLayers via element.innerHTML. An Editor can set a textbox variable's default value to an XSS payload that executes for every user who opens the dashboard. This is a bypass of the CVE-2023-0507 fix

CVSS3: 7.3
EPSS: Низкий
github логотип

GHSA-9493-h4f5-633x

3 месяца назад

The Tempo and Loki datasource plugins construct backend HTTP requests by interpolating user-supplied input into URL paths without sanitization, enabling path traversal. A Viewer-role user can: (1) capture admin-configured datasource credentials (secureJsonData custom headers) by traversing to an attacker-controlled endpoint, (2) invoke state-changing admin endpoints on Tempo (e.g. /flush, /shutdown), and (3) exfiltrate internal service data via Loki's CallResource which returns full HTTP response bodies.

CVSS3: 5.4
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
1
redhat логотип
CVE-2026-33382

Several Grafana API endpoints, some of them unauthenticated, do not limit the size of the request body before processing it. An attacker can send very large payloads that force excessive memory allocation, potentially exhausting memory and causing a denial of service.

CVSS3: 5.3
0%
Низкий
3 месяца назад
github логотип
GHSA-x94r-qqxh-wpj5

The public dashboard deletion endpoint does not enforce organization isolation, allowing an Org Admin in one organization to delete public dashboards belonging to a different organization by supplying the target dashboard's identifiers.

CVSS3: 3.1
0%
Низкий
3 месяца назад
nvd логотип
CVE-2026-28378

The public dashboard deletion endpoint does not enforce organization isolation, allowing an Org Admin in one organization to delete public dashboards belonging to a different organization by supplying the target dashboard's identifiers.

CVSS3: 3.1
0%
Низкий
3 месяца назад
redhat логотип
CVE-2026-28378

The public dashboard deletion endpoint does not enforce organization isolation, allowing an Org Admin in one organization to delete public dashboards belonging to a different organization by supplying the target dashboard's identifiers.

CVSS3: 3.1
0%
Низкий
3 месяца назад
fstec логотип
BDU:2026-12021

Уязвимость платформы для мониторинга и наблюдения Grafana, связанная с недостатками контроля доступа. Эксплуатация уязвимости может позволить нарушителю повысить свои привилегии

CVSS3: 2.7
0%
Низкий
3 месяца назад
github логотип
GHSA-3w66-95m3-8jxg

The public dashboard query endpoint does not limit request body size before processing, allowing unauthenticated attackers to trigger excessive memory allocation by sending arbitrarily large JSON payloads. This can lead to denial of service through memory exhaustion. No valid dashboard access token or authentication is required to exploit this vulnerability.

CVSS3: 7.5
0%
Низкий
3 месяца назад
nvd логотип
CVE-2026-42127

The public dashboard query endpoint does not limit request body size before processing, allowing unauthenticated attackers to trigger excessive memory allocation by sending arbitrarily large JSON payloads. This can lead to denial of service through memory exhaustion. No valid dashboard access token or authentication is required to exploit this vulnerability.

CVSS3: 7.5
0%
Низкий
3 месяца назад
ubuntu логотип
CVE-2026-42127

The public dashboard query endpoint does not limit request body size before processing, allowing unauthenticated attackers to trigger excessive memory allocation by sending arbitrarily large JSON payloads. This can lead to denial of service through memory exhaustion. No valid dashboard access token or authentication is required to exploit this vulnerability.

CVSS3: 7.5
0%
Низкий
3 месяца назад
github логотип
GHSA-9g84-39mm-q4p3

The geomap panel's XYZ tile layer has a sanitize-then-interpolate ordering bug. sanitizeTextPanelContent() runs on the raw template string before getTemplateSrv().replace() substitutes the variable value, which uses the glob format with no HTML escaping. The result is passed to OpenLayers via element.innerHTML. An Editor can set a textbox variable's default value to an XSS payload that executes for every user who opens the dashboard. This is a bypass of the CVE-2023-0507 fix

CVSS3: 7.3
0%
Низкий
3 месяца назад
github логотип
GHSA-9493-h4f5-633x

The Tempo and Loki datasource plugins construct backend HTTP requests by interpolating user-supplied input into URL paths without sanitization, enabling path traversal. A Viewer-role user can: (1) capture admin-configured datasource credentials (secureJsonData custom headers) by traversing to an attacker-controlled endpoint, (2) invoke state-changing admin endpoints on Tempo (e.g. /flush, /shutdown), and (3) exfiltrate internal service data via Loki's CallResource which returns full HTTP response bodies.

CVSS3: 5.4
0%
Низкий
3 месяца назад

Уязвимостей на страницу


Поделиться